Impact
The vulnerability is a reflected cross‑site scripting flaw (CWE‑79) in the login page of IBM Tivoli System Automation Application Manager and WebSphere Application Server. It allows an attacker to inject arbitrary client‑side scripts that execute in the context of administrators who access the console, potentially enabling session hijacking, credential theft, or other malicious actions that compromise confidentiality, integrity, and availability of the managed environment.
Affected Systems
IBM Tivoli System Automation Application Manager version 4.1 and IBM WebSphere Application Server versions 8.5 and 9.0 are affected. The specific security bulletins for these product releases provide the relevant patch details.
Risk and Exploitability
The attack vector requires a user to interact with the vulnerable login page, typically via a crafted URL or a malicious link. An attacker can lure a privileged user into executing the injected scripts, then hijack the session or steal credentials. The CVSS score of 9.3 indicates high severity, while the EPSS score of < 1 % and the lack of a KEV listing suggest that exploitation is unlikely at present but the vulnerability remains high risk and requires immediate action.
OpenCVE Enrichment